Author Topic: svchost.exe malware  (Read 3801 times)

0 Members and 3 Guests are viewing this topic.

REDACTED

  • Guest
svchost.exe malware
« on: June 08, 2015, 01:56:35 AM »
have warning popping up of svchost.exe 
log from malwarebytes



Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: svchost.exe malware
« Reply #1 on: June 08, 2015, 02:07:25 AM »
follow instructions  https://forum.avast.com/index.php?topic=53253.0

malware team will be back online tomorrow ...


REDACTED

  • Guest
Re: svchost.exe malware
« Reply #2 on: June 08, 2015, 02:11:37 AM »
ok thanks

REDACTED

  • Guest
Re: svchost.exe malware
« Reply #3 on: June 08, 2015, 02:21:50 AM »
frst log and addition log

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: svchost.exe malware
« Reply #4 on: June 08, 2015, 03:34:42 AM »
Hello,


Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on icon and select Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
Code: [Select]
createsrpoint;
autoclean;
emptyalltemp;
ipconfig /flushdns;b
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)
Post its content into your next reply.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: svchost.exe malware
« Reply #5 on: June 08, 2015, 10:44:25 PM »
alwaysisobar came up after reboot

log

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: svchost.exe malware
« Reply #6 on: June 08, 2015, 11:23:03 PM »
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content into your next reply.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: svchost.exe malware
« Reply #7 on: June 08, 2015, 11:29:54 PM »
logs

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: svchost.exe malware
« Reply #8 on: June 09, 2015, 08:18:59 AM »
How this issue started?
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: svchost.exe malware
« Reply #9 on: June 09, 2015, 09:32:45 PM »
not sure about how it started. maybe 2-4 weeks ago it just came up one day.  it was many warnings, but now its just the alwaysisobar only. all other warning have stopped.    would you like me to re run everything from the start with malwarebytes on down.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: svchost.exe malware
« Reply #10 on: June 10, 2015, 08:45:16 AM »
Fix with ZOEK

This fix was created for this user for use on that particular machine.
Running it on another one may cause damage and render the system unstable.

Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on icon and select Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
Code: [Select]
createsrpoint;
ffdefaults;
chrdefaults;
bitsadmin /reset /allusers;b
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)
Post its content into your next reply.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: svchost.exe malware
« Reply #11 on: June 11, 2015, 10:49:47 PM »
not sure what has happened, but zoek will not run. I tried it 3 times yesterday, the program starts and I copy the script into it and start scan and it starts working but never finishes.  I left it going all night and today through my work hours and just got home to see the same window open.  it just won't finish running. 

don't know when you will get back to me. I'll try and run malwarebytes again along with the other programs you had me use to get some more logs for you.  we'll see what happens
   
« Last Edit: June 11, 2015, 10:55:05 PM by basssc1 »

REDACTED

  • Guest
Re: svchost.exe malware
« Reply #12 on: June 12, 2015, 12:24:11 AM »
ok so I have been on pc for about an hour now with no pop up's.  its all to weird for me haha . anyway take a look at these new logs and tell me if I'm out of this mess
Thanks

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: svchost.exe malware
« Reply #13 on: June 12, 2015, 02:02:06 PM »
Yes, Zoek probably did its job :)

Is everything okay now?
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: svchost.exe malware
« Reply #14 on: June 12, 2015, 11:11:29 PM »
ok, I've been on for about 2 hours now and no more pop up warnings....  I think you got !!!
thanks